Governance package
A fictional collection of charters, responsibility maps, policies, standards, controls, evidence, decisions, exceptions, metrics, and review records.
Complete an integrated fictional Northbridge case combining governance, assets, data, business impact, risk assessment, treatment, controls, policies, exceptions, suppliers, metrics, leadership reporting, validation, and review.
Lesson Progress
High School Intermediate • I14: Security Policies and Risk • Lesson 8 of 8
Readiness Check
0/5 ready
Integrated Case
The fictional Northbridge leadership team has asked for one integrated review. The organization has an overdue security policy, active supplier access under an expired exception, unclear business recovery ownership, an untested backup assumption, cloud concentration, partial storage evidence, misleading metric scope, and an unowned supplier-offboarding lesson. Your job is to convert these records into accountable, prioritized, evidence-based decisions without exaggerating incidents or impact.
Weak integrated response
Label everything critical, assume compromise, recommend every control, ignore authority and dependencies, and provide a dashboard with no decisions or evidence limits.
Professional integrated response
Define scope, map ownership, validate evidence, structure risk, compare treatment, prioritize active exposure, preserve limits, assign decisions, test controls, and report clearly.
Objective 1
Integrate fictional governance, assets, data, business impact, risk assessment, treatment, standards, exceptions, suppliers, metrics, reporting, and review into one defensible case.
Objective 2
Separate fictional direct observations, supported conclusions, assumptions, alternatives, uncertainty, missing evidence, potential impact, confirmed impact, and decision authority.
Objective 3
Build a fictional governance and risk package with owners, evidence, controls, treatment, deadlines, validation, residual-risk decisions, monitoring, and closure criteria.
Objective 4
Prioritize fictional actions using business criticality, active exposure, control health, supplier dependency, recovery needs, confidence, and implementation readiness.
Objective 5
Create a portfolio-safe fictional capstone artifact that demonstrates professional reasoning without using real organizational records, credentials, incidents, or private data.
Core Model
Scope
Define the fictional business question, services, data, suppliers, users, owners, authority, time window, and privacy limits.
Evidence
Validate fictional relevance, health, completeness, timeliness, independence, traceability, assumptions, and limitations.
Risk
Connect fictional assets, threats, vulnerabilities, exposure, controls, likelihood, impact, confidence, and dependencies.
Decision
Select fictional treatment, controls, owners, approvals, deadlines, exceptions, communication, and residual-risk authority.
Validation
Test fictional security outcome, business function, evidence, monitoring, recovery, closure, and reassessment triggers.
Key Vocabulary
A fictional collection of charters, responsibility maps, policies, standards, controls, evidence, decisions, exceptions, metrics, and review records.
A fictional record of scenarios, assets, threats, vulnerabilities, controls, likelihood, impact, confidence, owners, treatments, and review dates.
A fictional analysis of critical services, dependencies, disruption effects, recovery objectives, minimum service, and recovery priorities.
A fictional statement describing the business or security outcome that a safeguard must achieve.
The fictional risk remaining after current or planned controls, limitations, dependencies, exceptions, and uncertainty are considered.
A fictional alternate safeguard that addresses the same control objective when the preferred control is temporarily impractical.
A fictional approved and time-bound departure from a requirement with narrow scope, owners, controls, residual risk, expiration, monitoring, and sunset planning.
A fictional risk arising from suppliers, service providers, software components, data processors, subcontractors, or external dependencies.
A fictional description of a metric’s purpose, scope, numerator, denominator, exclusions, source, frequency, target, threshold, owner, and limits.
A fictional judgment about how strongly the supplied records support a conclusion.
The fictional approved power to accept risk, approve policy, authorize an exception, fund treatment, escalate delay, or close a finding.
Fictional evidence that a control, recovery path, process, exception removal, supplier exit, or corrective action works as intended.
Fictional conditions that must be satisfied before a finding, risk, exception, treatment, or action is considered complete.
A fictional date or event that requires renewed review, such as a major change, failed test, incident, supplier change, deadline, or evidence gap.
A fictional concise report that translates technical and risk evidence into business meaning, uncertainty, options, ownership, and decisions.
A statement confirming that all organizations, systems, identities, suppliers, records, incidents, and evidence in the artifact are fictional.
Case Overview
Direct observation
The fictional Information Security Policy is overdue for annual review.
Supported meaning
Current owners, scope, requirements, and business priorities need formal reassessment.
Evidence limit
An overdue review does not prove the policy or controls are ineffective.
Direct observation
One fictional support-vendor account remains active after the project and exception ended.
Supported meaning
The account requires immediate removal or narrow authorized renewal.
Evidence limit
No unauthorized use, malicious intent, or disclosure is confirmed.
Direct observation
The fictional Reporting Service has technical operators but no confirmed business recovery risk owner.
Supported meaning
Business authority for recovery priority and residual risk is unclear.
Evidence limit
Technical recovery failure is not proven.
Direct observation
One fictional historical support collection is outside backup scope because the owner believes it can be reconstructed.
Supported meaning
Reconstruction must be tested or recovery protection added.
Evidence limit
No current data loss is confirmed.
Direct observation
The fictional dashboard reports ninety-eight percent policy compliance without a documented denominator or excluded-system list.
Supported meaning
Organization-wide interpretation is unsupported.
Evidence limit
The measured systems may still perform strongly.
Direct observation
Several fictional critical services depend on one cloud platform.
Supported meaning
Regional, recovery, evidence-access, and exit planning require review.
Evidence limit
No provider-controlled outage or incident is shown.
Direct observation
A fictional supplier-offboarding lesson remains open without a policy or procedure owner.
Supported meaning
The weakness may recur unless converted into owned governance and control changes.
Evidence limit
Some operational improvement may exist outside the supplied tracker.
Direct observation
One fictional storage source provides partial rather than complete object-level activity evidence.
Supported meaning
Monitoring confidence is reduced and compensating evidence must be reviewed.
Evidence limit
Partial evidence does not prove compromise.
Evidence Register
Supports
Policy owner, approval, version, effective date, review cycle, current status, and overdue review.
Source health
Current metadata; policy content requires formal review.
Limitation
Does not prove daily control operation.
Supports
Account status, sponsor, project end, role scope, exception expiration, and service boundary.
Source health
Account and exception records are current.
Limitation
Post-expiration activity coverage is incomplete.
Supports
Critical services, data, suppliers, owners, identities, networks, recovery dependencies, and concentration.
Source health
Most records are current; one recovery owner is missing.
Limitation
Informal dependencies may exist outside the register.
Supports
Risk scenarios, inherent and residual scores, confidence, treatment status, owners, and review dates.
Source health
Current enough for the lab; one acceptance review is overdue.
Limitation
Several scores depend on incomplete activity or ownership evidence.
Supports
RTO, RPO, technical restore, minimum service, user validation, dependencies, and exercise outcomes.
Source health
Technical records are complete; business validation is partial.
Limitation
One exercise does not guarantee future recovery.
Supports
Requirements, scope, business reason, controls, approvals, expiration, monitoring, residual risk, and sunset actions.
Source health
Current; one exception is expired and one request is incomplete.
Limitation
Exception documentation does not prove compensating-control effectiveness.
Supports
Criticality, contracts, access, data, control evidence, incidents, recovery, fourth parties, and exit readiness.
Source health
Mostly current; one report’s service and region scope is unclear.
Limitation
One assurance report cannot prove every supplier control.
Supports
Compliance, access review, supplier evidence, recovery, exception currency, source health, treatment progress, and improvement closure.
Source health
Values are current; several definitions need correction.
Limitation
Percentages may hide exclusions, quality, and incomparable scopes.
Lab Workflow
Define the fictional business question, scope, assets, services, data, suppliers, owners, authority, evidence, time window, privacy boundary, and expected decisions.
Deliverable: Integrated lab charter.
Assign fictional executive, risk, policy, control, asset, data, supplier, recovery, metrics, incident, review, and escalation responsibilities.
Deliverable: Responsibility and authority matrix.
Connect fictional services, data, users, identities, suppliers, processes, facilities, dependencies, criticality, RTO, RPO, minimum service, and recovery priorities.
Deliverable: Asset, dependency, and BIA package.
Document fictional threats, vulnerabilities, exposure, controls, likelihood, impact, assumptions, confidence, alternatives, limits, and owners.
Deliverable: Integrated risk register.
Compare fictional avoid, reduce, transfer, accept, and monitor options with control objectives, business fit, dependencies, validation, rollback, and residual risk.
Deliverable: Treatment and control plan.
Map fictional policies, standards, baselines, procedures, guidelines, controls, evidence, exceptions, approvals, expiration, monitoring, and sunset plans.
Deliverable: Document hierarchy and exception register.
Evaluate fictional supplier scope, access, data, contract controls, concentration, evidence, incidents, recovery, exit, metric definitions, source health, trends, and leadership meaning.
Deliverable: Supplier and metrics review.
Rank fictional actions, assign owners and deadlines, document leadership decisions, validate controls, define reassessment triggers, and produce technical and executive summaries.
Deliverable: Final governance and risk package.
Required Portfolio Artifacts
Integrated lab charter with scope, authority, evidence boundary, privacy boundary, owners, deliverables, and decision deadlines.
Governance responsibility matrix covering executive, risk, policy, control, asset, data, supplier, recovery, metrics, incident, review, and escalation roles.
Asset, service, data, supplier, user, dependency, classification, criticality, RTO, RPO, minimum service, and recovery-priority register.
Evidence-quality register with relevance, source health, independence, timeliness, completeness, consistency, traceability, confidence, and limitations.
Risk register with structured scenarios, controls, inherent and residual likelihood and impact, assumptions, alternatives, owners, treatments, and review triggers.
Risk-treatment and control-selection plan with control objectives, business fit, implementation sequence, validation, rollback, monitoring, and residual-risk approval.
Policy, standard, baseline, procedure, guideline, control, evidence, exception, waiver, approval, review, and sunset hierarchy.
Third-party and supply-chain register with services, fourth parties, software components, data, access, responsibilities, concentration, incidents, recovery, monitoring, and exit.
Metrics catalog with purpose, scope, numerator, denominator, exclusions, source health, target, threshold, trend, confidence, owner, business meaning, and actions.
Technical report, leadership summary, action register, validation plan, reassessment plan, reflection, and portfolio-safety statement.
Integrated Case Records
Facts
Project ended; exception expired; one limited account remains active; post-expiration activity evidence is incomplete.
Risk
Medium likelihood and High potential impact with Medium-High confidence.
Decision
Remove or narrowly renew through authorized governance.
Validation
Account is removed or matches renewed scope; approved support remains functional; monitoring is healthy.
Evidence limit
No unauthorized use or disclosure is confirmed.
Facts
Reporting Service has a procedure, two technical operators, and a four-hour RTO, but no business recovery owner.
Risk
Medium likelihood and High potential impact with Medium confidence.
Decision
Assign business authority and repeat user validation.
Validation
Owner approves priority, minimum service, exercise result, and residual risk.
Evidence limit
Technical recovery failure is not proven.
Facts
One confidential historical collection is outside backup scope; the owner claims it can be reconstructed.
Risk
Residual risk cannot be finalized until reconstruction evidence exists.
Decision
Run a timed reconstruction test or add backup coverage.
Validation
Reconstruction or restore meets approved RTO, completeness, integrity, and access requirements.
Evidence limit
No current data loss is confirmed.
Facts
Dashboard shows ninety-eight percent compliance; excluded legacy systems and denominator are not documented.
Risk
Medium decision-quality risk with High confidence.
Decision
Correct the definition before organization-wide use.
Validation
A reviewer can reconstruct the calculation, scope, exclusions, source health, and trend.
Evidence limit
Measured-system performance may be strong.
Facts
Learning, identity, storage, monitoring, and recovery capabilities rely on one fictional cloud platform.
Risk
High structural concentration with Medium-Low current service risk.
Decision
Maintain tested regional recovery, internal evidence access, data portability, and exit planning.
Validation
Recovery and exit exercises demonstrate minimum service, data access, evidence preservation, and owner decisions.
Evidence limit
No provider-controlled incident is shown.
Facts
One storage collection has function-level and change evidence but incomplete object-level activity logs.
Risk
Medium monitoring and investigation risk.
Decision
Maintain compensating controls and replace the connector within the approved exception window.
Validation
Expected object events arrive, parse, retain, alert, and support investigation.
Evidence limit
Partial evidence does not prove compromise.
Facts
Supplier-offboarding improvements were recommended, but policy and procedure ownership is missing.
Risk
Medium-High recurrence risk.
Decision
Assign owners, update the procedure, run an offboarding exercise, and validate closure.
Validation
Access, data, integrations, notifications, monitoring, knowledge transfer, and signoff complete on time.
Evidence limit
Some undocumented operational improvements may exist.
Facts
The Information Security Policy is six fictional months beyond its annual review date.
Risk
Medium governance risk with High confidence.
Decision
Complete stakeholder review, approval, publication, implementation mapping, and communication.
Validation
Current scope, owners, standards, controls, exceptions, training, and review dates are approved.
Evidence limit
The overdue review does not prove existing controls are ineffective.
Priority Action Plan
Why now
The fictional account remains active after project and exception closure, creating current capability and governance risk.
Deadline
Within one fictional business day
Closure proof
Removal or narrow renewal, activity review, service validation, monitoring, and owner signoff.
Why now
A fictional critical service lacks authority for recovery priority, minimum service, validation, and residual risk.
Deadline
Within three fictional business days
Closure proof
Named owner, approved objectives, exercise participation, decision record, and review date.
Why now
A fictional confidential historical collection depends on an untested reconstruction assumption.
Deadline
Within ten fictional business days
Closure proof
Timed reconstruction or restore test with completeness, integrity, access, and owner approval.
Why now
The fictional compliance metric lacks a denominator and exclusions, creating decision-quality risk.
Deadline
Before the next fictional leadership meeting
Closure proof
Definition, calculation, scope, exclusions, source health, confidence, trend, and action rules.
Why now
A fictional lesson learned remains unowned and may not become a lasting governance change.
Deadline
Within fifteen fictional business days
Closure proof
Updated policy and procedure, assigned roles, exercise, evidence, exceptions, monitoring, and closure.
Why now
The fictional policy is overdue and service, supplier, metric, recovery, and exception conditions have changed.
Deadline
Within thirty fictional days
Closure proof
Reviewed and approved version, stakeholder comments, control mapping, communication, and next review date.
Fake Dashboard
Training dashboard for fictional I14 lab evidence only.
Integrated records
8
Governance, supplier, recovery, backup, metrics, cloud concentration, monitoring, and improvement issues are mapped.
Immediate owner decisions
4
Stale access, recovery ownership, backup evidence, and metric scope require prompt decisions.
Confirmed incidents
0
The supplied fictional evidence supports control and governance gaps but no confirmed incident, misuse, outage, or disclosure.
Fake SOC Alert
Source: Fake I14 Integrated Lab Console • Time: 4:00 PM
Fake Log Panel
09:00 CHARTER scope='I14 integrated governance and risk lab' 09:10 GOVERNANCE policy-review='overdue' 09:20 SUPPLIER account='active' exception='expired' 09:30 RECOVERY business-owner='missing' 09:40 BACKUP historical-collection='excluded' 09:50 METRIC compliance='98%' denominator='undefined' 10:00 CLOUD concentration='multiple critical services' 10:10 LOGGING object-evidence='partial' 10:20 IMPROVEMENT supplier-offboarding owner='missing' 10:30 FINDING confirmed-incident='not supported' 10:40 PRIORITY stale-access='1' 10:50 PRIORITY recovery-ownership='2' 11:00 PRIORITY backup-validation='3' 11:10 PRIORITY metrics-correction='4' 11:20 VALIDATION business-and-security='required' 11:30 CLOSE owner-signoff-and-reassessment='required'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Common Mistakes
Final Lab Assignment
Your fictional assignment
Use only the fictional records on this page and the prior I14 lessons to produce a professional, decision-ready, portfolio-safe package.
Final quality standard
Scenario Decision Lab
The fictional supplier account is stale, but the service owner says one approved support task may still depend on it.
Scenario Decision Lab
The fictional leadership dashboard shows mostly favorable percentages while stale access, missing recovery ownership, backup uncertainty, and an unowned improvement remain open.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Integrated Security Policies and Risk Package for Northbridge. Include the charter, governance and authority matrix, asset and BIA register, evidence-quality register, risk register, treatment and control plan, policy hierarchy, exception register, supplier and supply-chain review, metrics catalog, priority action plan, validation and closure criteria, reassessment triggers, technical report, leadership summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation